Observed Signal · Jun 15, 2026 · Technical Release · Source: DEV Community · Impact: 2/5 · Sentiment: Neutral

3va: Rust-built JS/TS runtime with strict permissions

Executive Signal Summary

3va v2.0.2 is a JavaScript and TypeScript runtime implemented in Rust that enforces capability-based permissions by default. The runtime blocks filesystem, network, environment, child processes, and native addon access unless explicitly allowed, and it unconditionally prevents post-install scripts from running. 3va installs from standard registries (npm, Yarn, etc.), aims to be compatible with common frameworks (Next.js, React, Express, Fastify and others), and bundles a package manager, built-in process manager, test runner, bundler, DDoS protections, and post-quantum cryptography primitives. The author publishes benchmarks comparing 3va (debug build) with Node.js and Bun—acknowledging Bun’s superior raw throughput and startup—but emphasizes 3va’s security and permission isolation as its primary value. Multiple install channels are provided (npm, Homebrew, Chocolatey, Scoop, cargo, Flatpak).

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

A new permission-isolating JS/TS runtime addresses supply-chain and runtime security for JavaScript ecosystems, but it is an independent open-source runtime rather than a major platform change; therefore its immediate industry impact is modest.

SIGNAL RADAR

Track ARD Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • 3va v2.0.2 was released as a JavaScript/TypeScript runtime written in Rust.
  • 3va enforces capability-based permissions: filesystem, network, environment, child processes and native addons are blocked by default and must be explicitly allowed.
  • Post-install scripts are blocked unconditionally; the package manager does not execute them.
  • 3va installs from common registries (npmjs.org, Yarn, JSR) and aims to run popular frameworks (Next.js, Astro, Nuxt, SvelteKit, Remix, Gatsby, SolidStart, Qwik, Express, Fastify, Koa, NestJS, React Native).
  • Included features: package manager, built-in process manager (replaces pm2), test runner, bundler, dev server with HMR, DDoS protections, and post-quantum cryptography support (ML-KEM-768, ML-DSA-65).

Ontology Mapping & Concepts

Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: DEV Community•Published: Jun 15, 2026
Original Coverage Title: “I built a JS/TS runtime in Rust where nothing runs without your permission”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

Infrastructure / Runtime SecurityJun 15, 2026

3va: Rust JS/TS Runtime Enforces Runtime Permissions

The author released v2.0.0 of 3va, a JavaScript and TypeScript runtime implemented in Rust that enforces explicit, runtime-level permissions. 3va defaults all capabilities (filesystem, network, env vars, child processes, native addons) to blocked and requires an explicit permission declaration in package.json; post-install scripts are never executed. It is designed as a drop-in replacement for existing registries and frameworks (frontend and backend frameworks listed) and includes an integrated package manager, built-in process manager (auto-restart, persistent state), test runner, bundler, dev server, profiler, malware/audit tooling, and DDoS protections (hard connection limit 1,024 + Slowloris mitigation). The runtime exposes post-quantum crypto primitives (ML-KEM-768, ML-DSA-65) and a hybrid TLS API (__pqTlsConnect). The author notes honest benchmarks where 3va trades raw throughput/startup for stronger permission isolation.

Read assessment
InfrastructureJun 7, 2026

Secure Code Execution Sandbox Built in Rust

A developer describes Custody, a Rust-based secure code execution sandbox built as a layered defense against attacks such as fork bombs, memory exhaustion, network exfiltration, syscall abuse, and infinite loops. The design stacks gVisor (runsc with --network=none and --no-new-privs) as an outer syscall interposer, cgroups v2 for CPU, memory, PID and wall-time limits, and seccomp syscall allowlists as the innermost kernel-level filter. Additional protections include output caps, OOM detection via cgroup memory.current, and a labeled kill-reason taxonomy (timeout_wall, output_limit, oom, seccomp_violation, clean) to improve auditability. The author reports 100% containment across eight tested attack scenarios and lists planned v2 improvements: prebuilt OCI rootfs images, pidfd_open+epoll for instant process exit detection, and automated seccomp generation using eBPF or strace.

Read assessment
Developer Tool / CLIMay 11, 2026

jray: JSON CLI Built with Bun and TypeScript

A developer built and published jray, a small open-source JSON CLI written in TypeScript and compiled with Bun. jray flattens JSON to dot-notation, supports glob-style filtering, colorized TTY output, NDJSON streaming, and can fetch JSON from URLs. The project compiles to a single binary via bun build --compile and is published to npm as @siyadkc/jray with source on GitHub. The author documents practical issues encountered (npm name conflict requiring a scoped package, large npm package payload until files was set, Windows postinstall chmod failures, and CI lockfile handling) and shares CI/publishing tips and a live GitHub Pages playground.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.